US 11,706,247 B2
Detection and prevention of external fraud
Yu Zhou Lee, San Francisco, CA (US); Lawrence Stockton Moore, San Francisco, CA (US); Jeshua Alexis Bratman, New York, NY (US); Lei Xu, New York, NY (US); and Sanjay Jeyakumar, Berkeley, CA (US)
Assigned to Abnormal Security Corporation, San Francisco, CA (US)
Filed by Abnormal Security Corporation, San Francisco, CA (US)
Filed on Jul. 29, 2022, as Appl. No. 17/877,768.
Application 17/877,768 is a continuation of application No. 17/491,184, filed on Sep. 30, 2021, granted, now 11,457,038.
Application 17/491,184 is a continuation of application No. 17/239,152, filed on Apr. 23, 2021.
Claims priority of provisional application 63/014,421, filed on Apr. 23, 2020.
Prior Publication US 2022/0368718 A1, Nov. 17, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04L 51/08 (2022.01); H04L 51/212 (2022.01)
CPC H04L 63/1433 (2013.01) [H04L 51/08 (2013.01); H04L 51/212 (2022.05); H04L 63/0236 (2013.01); H04L 63/0245 (2013.01); H04L 63/126 (2013.01); H04L 63/145 (2013.01)] 22 Claims
OG exemplary drawing
 
1. A system, comprising:
a processor configured to:
obtain an email that is addressed to a first email account associated with a first enterprise;
establish, at least in part by examining content of the email, that the email was sent by a second email account associated with a vendor;
access a database to identify a digital profile associated with the vendor, wherein the digital profile includes a record of a set comprising a plurality of past emails sent by the second email account, wherein the digital profile is a first digital profile included in a set of digital profiles collectively associated with a plurality of vendors, and wherein at least one email included in the set of past emails is addressed to an email account associated with a second enterprise that is different from the first enterprise; and
determine, based on the digital profile, whether the email differs from the set of past emails in terms of context and/or content to such a degree that compromise of the second email account is likely; and
a memory coupled to the processor and configured to provide the processor with instructions.